CVE-2023-37482 Details
Description
The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.
A user enumeration vulnerability has been identified in the web server of several Siemens SIMATIC products. This vulnerability arises because the login functionality does not normalize response times for login attempts, allowing an unauthenticated remote attacker to exploit this side-channel information to differentiate between valid and invalid usernames. The vulnerability affects various SIMATIC products, including the Drive Controller family, ET 200SP Open Controller CPU 1515SP PC2 (including SIPLUS variants), S7-1200 CPU family V4 (including SIPLUS variants), S7-1500 CPU family (including related ET 200 CPUs and SIPLUS variants), S7-1500 Software Controller, and S7-PLCSIM Advanced. The vulnerability is considered exploitable only via HTTP.
Siemens has released patches for the affected products. Users are advised to update to the latest versions. For specific update instructions, refer to the Siemens support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 11, 2025CISA-ADP
Assessed Feb 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-195895.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens SIMATIC Drive Controller | All versions |
CPE
Remediation
| |
| Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 | All versions |
CPE
Remediation
| |
| Siemens SIMATIC S7-1200 CPU | All versions |
CPE
Remediation
| |
| Siemens SIMATIC S7-1500 CPU | All versions |
CPE
Remediation
| |
| Siemens SIMATIC S7-1500 Software Controller | All versions |
CPE
Remediation
| |
| Siemens SIMATIC S7-PLCSIM Advanced | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | New CVE Received | [email protected] |
Volerion